Guest
As part of ISO 27001 Supplier relationships A.15 and specifically to supplier’s risk assessment, management has taken a decision that as a small-business size, the risk assessment for the critical suppliers will be performed mostly through an online audit for example, undertaking further research by checking Google, review website and social media pages and on extremely rare occasions, further steps like: asking for NDAs and/or providing awareness training will be actioned.
In the light of the above, would that be sufficient in terms of ISO 27001 certification and can you recommend any tool or even resource that could assist us in audit suppliers online.
I noticed that the risk register within Confirmio is built with asset-focused method of doing risk assessment (as per version 27001:2005). However, with version of 27001:2013, the risk assessment method is using information-focused (6.1.2.c.1).
My question is do you have a risk register module that follows information-focused approach?
I need your answer as an expert, but not as a commercial vendor, then I need to know if I´ll received value added if I buy your ISO 22301 Toolkit for my actually project.
Please let me know, from expert to expert, if this make sense for me or not. If you told me it`s make really sense and will helpful for me to implement the BCM project, then I`ll make an order to you. Perhaps, you`ll remember me as a client and you`ll make me a special offer for this BCM-Toolkit.
I really appreciate an expert answer from you.